Quantifies the 'ephemeral author' risk and identifies 'dependency hiding' and industrialized code reuse as the primary tactics for supply chain malware.
A large-scale analysis of 24,356 malicious OSS packages reveals that while the volume is high, code diversity is low due to industrialized reuse: only 153 distinct code groups were found in a 2,915-package PyPI subset. Most malicious packages (74.5%) are authored by ephemeral accounts that publish only a single package, rather than from account takeovers. A significant trend is the 'dependent-hidden' attack, where 28 malicious packages (like 'util' or 'urllib') were reused as hidden dependencies by 1,354 other malicious packages to evade detection. These hidden attacks have a very short average active period of 10.5 days, while repeated attempts using similar code persist for approximately 45 days. The research identifies 1,449 malicious URLs and 234 C2 IP addresses in security reports, with the '.ru' domain being the most frequent host for command-and-control infrastructure.
The research analyzed over 24,000 real-world malicious packages, documenting thousands of instances of data exfiltration and C2 beaconing.
compromise of credentials and permanent loss of sensitive system data through intentionally malicious dependencies
identifying active malware is the final and most critical control for supply chain security, validated by the 1,300% growth in repository threats.
74.5% of identified malware comes from brand-new accounts that have only ever published a single package, highlighting the high risk of new repositories.
installing malicious code from a throwaway account with no established reputation
the 'single-package ephemeral account' is the statistically dominant profile for malicious supply chain attackers across all major ecosystems.
74.5% of malware packages were authored by an account that only published one package... net new accounts.
Risk Guard evaluates author reputation but doesn't explicitly weight the 'Account Age' or 'Single-Package Status' as a primary malware signal.
Risk Guard would be better if it flagged 'Ephemeral Authors' who publish a single package from a brand new account as a high-risk indicator.